Field notes & writing

Writing as the cheapest way to think clearly.

Long-form essays, runbooks, and lessons from real engagements. No SEO-fluff. If a post is here it's because someone asked the question twice and I got tired of rewriting the answer.

Featured · Cybersecurity
// long read · 14 min read
15 May 2026

The SOC analyst who refused to be a button-pusher: notes from rebuilding a SIEM that nobody trusted

A long-form story about taking over an alert pipeline that was generating 1,800 false-positives a week and turning it into a tight, MITRE-aligned detection engine. Includes the rule-tuning playbook we still use today.

Cybersecurity
08 May 2026·9 min read

Detection engineering for humans: a working framework

Why most "best practice" rules fail in production, and a simpler hypothesis → rule → review loop that holds up.

Read post
Web Dev
02 May 2026·11 min read

Next.js 15 in anger: what server actions changed for real apps

A frank look at where server actions are great, where they bite, and how to know which tool to reach for.

Read post
SEO
28 Apr 2026·7 min read

You're ranking for the wrong things. Here's the buyer-journey audit.

A 4-step audit to find the keywords that actually move pipeline — and quietly retire the ones that don't.

Read post
Career
21 Apr 2026·12 min read

How to break into SOC analysis without an IT degree

The exact 12-month plan I give every aspiring analyst who messages me on LinkedIn. With labs and timeline.

Read post
Cybersecurity
15 Apr 2026·8 min read

Tabletop exercises that don't suck: 6 scenarios that actually train the muscle

Most tabletops devolve into PowerPoint theatre. Here are scenarios that force real decisions under time pressure.

Read post
Marketing
08 Apr 2026·10 min read

The 5-pillar content engine for B2B founders who hate marketing

A repeatable monthly content system that works even when the founder is the marketing team.

Read post
Web Dev
02 Apr 2026·6 min read

Performance budgets, not performance tips: a forcing-function approach

Why I treat Core Web Vitals like a CI check, and how to wire it up so regressions never ship.

Read post
Cybersecurity
27 Mar 2026·7 min read

Cloud IAM is a security problem, not a DevOps one

A short manifesto + a checklist. The boring controls that prevent 80% of cloud incidents I see.

Read post
Newsletter

One essay, every two Fridays.

Cybersecurity, web engineering, and the systems that connect them. Long-form. Unsponsored. Easy to unsubscribe. Currently read by 8,400 operators.

Subscribe
8,400+ subscribers · 0 paid ads